← Back to the main page

Personal Data Processing Policy

Effective from 6 August 2026

This is an English translation provided for convenience. The Czech version is authoritative.

1. Who processes your data

The data controller is Marek Polcar, Company ID 03840131, registered at Keřová 716/5, 641 00 Brno, Czech Republic. The contact e-mail is [email protected]. I have not appointed a data protection officer; please contact me directly in all matters.

2. What data I process

3. Why I process the data

4. Who I share the data with

I do not sell your data to anyone. I rely on the following processors to run the service:

Processor What it is for What data is shared Where, and on what basis
Supabase database and sign-in account, kennel, dog and order data, and support messages European Union, data stays in the EU
Cloudflare image storage (R2), website hosting and bot protection on forms (Turnstile) photographs, generated flyers and technical data European Union, storage is bound to the European region
Google Gemini flyer creation dog photographs, the cynological details you enter and the contact details to be shown on the flyer United States, European Commission standard contractual clauses
Stripe payments e-mail and payment data United States, European Commission standard contractual clauses
Resend order confirmations and support message notifications e-mail, order data and support message content United States, European Commission standard contractual clauses
PostHog measuring how the website and the app are used technical data and an anonymous identifier European Union, the eu.posthog.com instance
EmailOctopus newsletter delivery e-mail, optionally your name and kennel name European Union (Ireland), with access from the United Kingdom under the European Commission adequacy decision

5. Photographs and artificial intelligence

This is the most important part of this policy, which is why I state it separately. The flyer comes about by my sending photographs of your dogs, the details you enter about them, and the contact details to be shown on the flyer, to Google for processing, specifically to the Gemini service. Without this transfer the flyer cannot be created; it is the essence of the service.

According to its terms for the paid Gemini API, Google does not use data sent through this interface to train its models. The current wording is available in the Google terms. If you do not want your photographs to reach this processor, please do not use the service.

By uploading a photograph you confirm that you hold the rights to it. With images taken by professional photographers this may not be a given, so please verify it before uploading.

6. How long I keep the data

I keep account, kennel and dog data and the created flyers for as long as your account exists. Purchased flyers are kept even after that, so you can download them again at any time. Tax records are kept for as long as the law requires. After your account is deleted I remove the data, except what I am legally required to retain. After your account is deleted I also remove the error reports and measurement records held in PostHog under your account identifier.

7. Your rights

You have the right to access your data, to have it corrected or erased, to restrict processing, to data portability and to object to processing based on legitimate interest. You can withdraw the newsletter consent at any time. Just write to [email protected] and I will get back to you within one month at the latest.

If you believe I process your data unlawfully, you can lodge a complaint with the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Praha 7, uoou.cz.

8. Cookies and usage measurement

The service needs only a minimum to run: the sign-in session stored in your browser and a cookie holding your answer from the consent bar. None of it tracks what you do elsewhere on the internet.

I measure the use of the kyna.cz website and the app.kyna.cz application with PostHog, which runs on servers in the European Union. In-browser measurement is the only part of the service that stores something on your device which is not needed to run it, which is why the bar at the bottom of the page asks you about it. Your answer is stored in a cookie whose name starts with __ph_opt_in_out_ and it covers both kyna.cz and app.kyna.cz at once, so answering once is enough.

Regardless of your answer, three things are recorded on the server side for measurement; besides the measurement there are two further records, described in the two paragraphs that follow. Error reports, so that service failures can be found and fixed: they contain your account identifier, the address where the error occurred, and up to fifteen lines of Kyna's own source code around each frame of the stack trace. A record of a completed purchase, at the moment of payment. And the progress of a signed-in user through flyer creation: the flyer being started and which control in the app started it, and the start, completion or failure of each generation, along with the generation mode, the round number, the number of variants and how long it took. No photograph, dog name or flyer text is sent to the measurement. The legal basis is performance of the contract for the purchase, and legitimate interest in the secure, functional and usable operation of the service for the error reports and the creation progress. These records are not produced in your browser and store nothing on your device, which is why the consent bar does not govern them.

Besides the measurement, I keep a record of the service performed on each flyer: when it was created, which wizard fields you saved and with what value, when generation ran and how many variants it produced, what you put in the basket and took out again, when you went to payment and when an order was created. It includes the text you type into the flyer yourself: the litter name, the mood description and the kennel details, because without them there is no way to establish afterwards what you were actually trying. Dog names are not stored, only their identifiers, and no photograph or finished flyer goes into this record. The legal basis is performance of the contract: it is the record of the service I provided to you, not measurement. The "Measure how I use the app" switch therefore does not cover this record, and that is deliberate: when you write to me that something did not work, it is the only thing that can establish what. I keep it for the life of the account and delete it together with the account. Deleting a flyer does not remove it: the flyer disappears from the app, but the record of the service I provided to you remains until the account is closed.

Besides the measurement, the server also keeps an operational request log. It is used to run and secure the service and to find faults: without it there is no way to establish afterwards what happened to you in the app. For each request the app sends to the server (api.kyna.cz) it records the time, the request method and address, the response code, how long it took, your account identifier if you are signed in, and the IP address the request came from. Request bodies and headers are not recorded, so flyer text, dog names, photographs and credentials never reach it. The log is kept for 30 days and then deleted automatically. The legal basis is legitimate interest in the secure and functional operation of the service. The "Measure how I use the app" switch does not cover this log, just as it does not cover error reports: without the operational log I could neither find a fault nor evidence it.

You can change your cookie decision at any time: click "Privacy settings" in the website footer or in the account menu in the app and the bar will appear again. You can object to the measurement of flyer creation in PostHog, which rests on legitimate interest: turn off the "Measure how I use the app" switch in the Profile section of the app, or write to me at [email protected]. Error reports do not stop with it, without them I would not find service failures, and neither the record of the service performed nor the operational request log described above stops with it either: both rest on a different basis and are described separately. IP addresses are anonymised in the PostHog measurement and I do not use screen recording; the operational request log described above does store an IP address, for 30 days.

9. Changes to this policy

I may update this policy. The current version is always available on this page and is marked with the effective date shown at the top.